Skip to main content
← Back to list
01Issue
FeatureOpenExtensionsPublic
AssigneesNone

Relationships

#2527 @swamp/aws/certificatemanager/certificate: expose ACM's reported attributes (NotAfter, Type, RenewalEligibility, InUseBy) on read

Opened by kscarmardo-glu · 9/25/2026

Problem

@swamp/aws/certificatemanager/certificate get returns only:

CertificateArn, DomainName, KeyAlgorithm, SubjectAlternativeNames, _identifier

Absent are every attribute ACM's own DescribeCertificate reports: NotAfter, NotBefore, Type, Status, RenewalEligibility, InUseBy, RenewalSummary.

Those are the fields you would read a certificate to find out. Without them the type can enumerate certificates but cannot answer whether any of them is about to break something.

Why this matters more than it looks

The two decisive facts are when it expires and whether it can renew itself, and neither is useful alone.

In one account we measured:

Domain Type Days left Auto-renews
mcp-lab-dev.… AMAZON_ISSUED 56 yes — unremarkable
*.example.com IMPORTED 54 no — an outage with a date on it

Two days apart, opposite meanings. A consumer with only DomainName cannot distinguish them, and a consumer with only an expiry date would alarm on both or neither.

This is not hypothetical: we found an IMPORTED, RenewalEligibility: INELIGIBLE wildcard three days from expiry, live on a production load balancer, with nothing watching it. The model could not have surfaced that.

Proposal

Include ACM's reported attributes in the read path for @swamp/aws/certificatemanager/certificate.

More generally, this is the same root cause as swamp-club Lab #2487, seen from the other side: there the generated read schema marks declare-time properties as required; here it omits report-time properties. Both follow from generating the read path from a resource schema describing what can be declared rather than what the service reports. A fix at the generator would address both, and likely other @swamp/aws/* types.

Current workaround

A local export const extension adding a check_expiry method that calls DescribeCertificate directly and records days-remaining plus a computed autoRenews. It works, and the extension guide's step 5 explicitly says to file this request when extending an official type — but every consumer wanting certificate expiry has to write the same thing.

Environment

  • swamp 20260923.133857.0-sha.819937e2
  • @swamp/aws/certificatemanager model type version 2026.08.29.1

Upstream repository: https://github.com/swamp-club/swamp-extensions

Environment

  • Extension: @swamp/aws/certificatemanager@2026.09.24.1
  • swamp: 20260923.133857.0-sha.819937e2
  • OS: darwin (aarch64)
  • Deno: 2.9.7
  • Shell: /bin/bash
02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/25/2026, 12:41:58 PM

No activity in this phase yet.

03Sludge Pulse
Editable. Press Enter to edit.

system commented 9/25/2026, 12:41:58 PM

Classified automatically when this issue was filed.

  • Source: Extensions

If you feel this classification is incorrect, add a ripple to tell us so.

Sign in to post a ripple.